Enforcing Robust Declassification and Qualified Robustness

Enforcing Robust Declassification and Qualified Robustness
复制标题

实施稳健解密和合格稳健性

DOI:
--
复制
发表时间:
2006
期刊:
Journal of computing and security
影响因子:
--
通讯作者:
Steve Zdancewic
Steve Zdancewic
中科院分区:
--
文献类型:
--
作者:
A. Myers;A. Sabelfeld;Steve Zdancewic

文献摘要

被引文献

相似文献

不干扰要求在给定系统中没有从敏感数据到公共数据的信息流。然而,许多系统作为其预期功能的一部分释放敏感信息,因此违反了不干涉原则。为了在允许信息发布的同时控制信息流动,一些系统具有降级或解密机制,但这产生了可能导致无意信息发布的危险。本文表明,鲁棒性可以用来描述程序中的解密机制不能被攻击者控制,以释放更多的信息比预期的。它描述了一种简单的方法,通过基于类型的编译时程序分析来证明这种鲁棒性。本文还提出了一个泛化的鲁棒性,支持升级(背书)数据完整性。
Noninterference requires that there is no information flow from sensitive to public data in a given system. However, many systems release sensitive information as part of their intended function and therefore violate noninterference. To control information flow while permitting information release, some systems have a downgrading or declassification mechanism, but this creates the danger that it may cause unintentional information release. This paper shows that a robustness property can be used to characterize programs in which declassification mechanisms cannot be controlled by attackers to release more information than intended. It describes a simple way to provably enforce this robustness property through a type-based compile-time program analysis. The paper also presents a generalization of robustness that supports upgrading (endorsing) data integrity.